The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attackers to cause a denial of service .

A remote user can cause arbitrary code to be executed on the target user's system.A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on the target user's system.